The UK's approach to AI governance and safety, explained
Rather than a single AI law, the UK relies on existing regulators, voluntary commitments and international diplomacy to manage the risks of artificial intelligence, a strategy that is increasingly being tested as the technology advances.
Why this matters
Artificial intelligence is being embedded into healthcare, finance, education, policing and everyday consumer products, often faster than legislation can keep pace with it. How a country chooses to govern AI shapes not only the risks its citizens face, such as bias, misinformation or job disruption, but also whether AI companies choose to develop and deploy technology there. The UK has taken a distinctive path compared with the European Union and the United States, and understanding that path helps explain ongoing debates about regulation, investment and safety.
A principles-based, sector-led model
Unlike the European Union, which passed a comprehensive AI Act creating specific legal obligations tied to risk categories, the UK government has so far resisted introducing a single overarching AI law. Instead, its stated approach is “pro-innovation”: existing regulators, such as the Information Commissioner’s Office, the Financial Conduct Authority, the Competition and Markets Authority and the Medicines and Healthcare products Regulatory Agency, are expected to apply cross-cutting principles to AI within their own domains. These principles typically cover safety, transparency, fairness, accountability and contestability.
The rationale is that AI is not a single technology but a general-purpose tool used across very different sectors, so a regulator overseeing medical devices is better placed to judge AI-driven diagnostic tools than a brand new AI-specific authority would be. Critics counter that this creates gaps and inconsistencies, since not every sector has a regulator with the expertise, resources or legal powers to scrutinise AI systems effectively, and that a light-touch approach favours large incumbent technology firms over smaller competitors and the public.
Frontier AI and the Safety Institute
A second strand of UK policy focuses specifically on the most advanced, or “frontier”, AI systems, the kind of large models capable of unpredictable or potentially dangerous behaviour. The government established a dedicated body, originally called the AI Safety Institute, to evaluate these systems before and after release, testing for risks such as the ability to assist in cyberattacks, generate harmful biological or chemical information, or deceive users. This body works with, but sits outside, the traditional sectoral regulators, reflecting a view that frontier AI poses novel national security and safety questions that existing bodies were not designed to handle.
This institute collaborates with counterparts in other countries and with the AI companies themselves, which have made voluntary commitments to share access to their most powerful models for safety testing before wide deployment. These arrangements are not legally binding, which supporters see as a pragmatic way to move quickly given how fast the technology changes, and critics see as inadequate given the stakes involved.
International diplomacy and summits
The UK has also positioned itself as a convenor of international discussion on AI safety, hosting a summit at Bletchley Park in 2023 that brought together governments, researchers and AI companies from around the world, including the United States, China and the European Union, to discuss shared risks from advanced AI. This led to follow-on summits hosted by other countries and to collaborative efforts such as international scientific reports assessing the state of AI capabilities and risks, intended to give policymakers a shared evidence base independent of any single company’s claims.
This diplomatic role reflects a wider UK strategy of using scientific credibility and convening power to shape global norms, given that it does not have the market size of the EU or the US to unilaterally set standards that companies must follow worldwide.
Ongoing tensions
The UK’s approach remains under review. There have been repeated discussions about introducing targeted legislation focused specifically on the most powerful frontier models, partly in response to concerns that voluntary commitments are insufficient and partly to keep pace with binding rules emerging elsewhere, notably the EU’s AI Act. Balancing the ambition to attract AI investment and research against public concern over safety, copyright, misinformation and job displacement remains the central tension in UK AI policy, and it is likely to keep evolving as the technology itself does.